Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\RBXVLSRM] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\RBXVLSRM] 'ImagePath' = '%ALLUSERSPROFILE%\hrplewhcamac\Microsoft Store.exe'
- 'RBXVLSRM' %ALLUSERSPROFILE%\hrplewhcamac\Microsoft Store.exe
- Журнал событий Windows (Windows Event Logging)
- <SYSTEM32>\conhost.exe
- %ALLUSERSPROFILE%\hrplewhcamac\microsoft store.exe
- %WINDIR%\temp\ecjupvjkyyqi.sys
- DNS ASK lo###his.space
- DNS ASK ra#.####ubusercontent.com
- '%ALLUSERSPROFILE%\hrplewhcamac\microsoft store.exe'
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -hibernate-timeout-dc 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-ac 0
- '<SYSTEM32>\powercfg.exe' /x -standby-timeout-dc 0
- '<SYSTEM32>\sc.exe' delete "RBXVLSRM"
- '<SYSTEM32>\sc.exe' create "RBXVLSRM" binpath= "%ALLUSERSPROFILE%\hrplewhcamac\Microsoft Store.exe" start= "auto"
- '<SYSTEM32>\sc.exe' stop eventlog
- '<SYSTEM32>\sc.exe' start "RBXVLSRM"